World Congress 2026 North America
When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale
Yoav Gal, Dor Cohen
World Congress 2026 North America
World Congress 2026 North America
September 23–25, 2026 · San José, CA
Attend in person
Get ticketsWatch remotely
Pro
Can’t make it to San José? Watch this session live with Pro. You also get:
AI agents are moving from demos to production. They’re accessing databases, calling APIs, orchestrating workflows—but most lack basic security primitives that we’ve required for human users for decades.
This talk covers the security infrastructure layer every AI agent deployment needs:
The Challenge
Agents run with API keys: no identity, no audit trail, easy to leak
MCP servers proliferate without verification—shadow IT for the AI era
No visibility into what agents are doing or what they’re connecting to
The Solution: Three Pillars
Cryptographic Identity: Ed25519 keypairs give agents unforgeable identity. Not credentials that can be shared—proof of who they are.
MCP Server Attestation: Verify every MCP server before connection. Detect configuration drift. Know when tools change.
Behavioral Trust Scoring: Static allow/deny isn’t enough. Trust scores adapt based on agent behavior over time.
Live Demo I’ll secure an agent from scratch: generate identity, connect to attested MCP servers, enforce capability policies, and show the audit trail.
You’ll leave with patterns you can implement whether you use our open-source platform (AIM) or build your own. The concepts apply to LangChain, CrewAI, AutoGen, or any MCP-based system.
20 years of enterprise security lessons, applied to the AI agent era.
World Congress 2026 North America
Yoav Gal, Dor Cohen
World Congress 2026 North America
Ashok Prakash
Staff ML Engineer at Apple
World Congress 2026 North America
Borko Djurkovic
Member of Technical Staff at Cohere
World Congress 2026 North America
Vivek Pandit
Principal Engineer at Cadence